CVE-2017-6605 describes a reflective cross-site scripting (XSS) vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE). This flaw, affecting versions like 2.1(0.800), allows an authenticated, remote attacker to execute malicious scripts in a victim's browser. Rated with a CVSSv3 score of 5.4 (Medium), the vulnerability requires low privileges and user interaction (UI:R) for successful exploitation, with potential impacts on confidentiality and integrity (C:L, I:L). The attack vector is network-based (AV:N) and complexity is low (AC:L). There is no evidence of active exploitation, nor is public exploit code available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1\(0.800\)CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:2.1\(0.800\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.